> Markdown version of [/jobs/ext/200504-active-directory-security-engineer](https://www.wearedevelopers.com/jobs/ext/200504-active-directory-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Active Directory Security Engineer - **Company:** Matlen Silver - **Location:** Chandler, AZ, United States - **Experience:** Expert - **Salary:** $176,800.0 - $185,120.0 - **Contract:** Temporary contract - **Skills:** Active Directory, Domain Controllers, User Authentication, Authentication Protocols, Cyber Security, Cryptographic Protocols, Windows Domain, Windows PowerShell, Shell Script - **Published:** May 13, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=a8fe3a240717e75e ## About the Role Do you have experience in Shell Scripting?, * 10+ years of enterprise Active Directory engineering experience * Extensive experience with Active Directory architecture, design, and security engineering * Deep expertise in Group Policy Objects (GPO) design, management, and remediation * Strong PowerShell scripting skills for automation and AD policy management * Experience engineering enterprise-scale AD environments supporting multinational organizations * Advanced knowledge of Active Directory security architecture * Strong experience with domain controller design, build, and deployment * Deep understanding of authentication and encryption protocols Preferred Experience * Experience working in large financial or enterprise-scale environments * Experience with multi-forest Active Directory environments * Knowledge of Red Forest / Enhanced Security Administrative Environment (ESAE) models * Experience designing Bastion Forest architectures * Background in enterprise identity security and privileged access models ## Description Overview We are seeking a senior Active Directory Security Engineer to join a highly specialized engineering team responsible for the design, security, and architecture of a large-scale enterprise Active Directory environment. This is a pure engineering role focused on design, security hardening, and architecture-not operational support. The environment supports one of the largest Active Directory infrastructures globally, requiring deep experience in enterprise-scale AD security, architecture, and Group Policy design. Project Details * Project Focus: Active Directory Group Policy (GPO) cleanup and security hardening initiative * Phase: Active remediation and modernization of enterprise GPO structure * Environment: Large-scale enterprise AD infrastructure supporting a multinational organization * Work Type: Ongoing engineering initiatives focused on AD architecture, security posture, and policy design * Infrastructure: 100% on-premises domain environment, * Design, engineer, and secure large-scale Active Directory environments in an enterprise setting. * Lead Group Policy architecture, rationalization, and cleanup initiatives across complex AD domains. * Develop PowerShell automation to support GPO restructuring, auditing, and policy management. * Design and implement secure Active Directory architectures, including multi-forest and privileged access models. * Engineer and maintain Active Directory domain controller infrastructure. * Implement and maintain AD security best practices, including privileged access isolation and security boundary enforcement. * Evaluate and strengthen encryption protocols and authentication mechanisms across the AD environment. * Partner with security and infrastructure teams to maintain a hardened enterprise identity platform. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Beyond Prompting: Building Scalable AI with Multi-Agent Systems and MCP](https://www.wearedevelopers.com/videos/1454-beyond-prompting-building-scalable-ai-with-multi-agent-systems-and-mcp) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [MCP doesn’t suck — your agent does](https://www.wearedevelopers.com/videos/100202-mcp-doesn-t-suck-your-agent-does) - [Hacking MSSQL on Cloud. All of them. How I became sysadmin on Azure, AWS, GCP and Alibaba.](https://www.wearedevelopers.com/videos/100339-hacking-mssql-on-cloud-all-of-them-how-i-became-sysadmin-on-azure-aws-gcp-and-alibaba) - [Advanced Cypress: custom assertions and tasks](https://www.wearedevelopers.com/videos/790-advanced-cypress-custom-assertions-and-tasks) ## Related Articles - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [Everything a Developer Needs to Know About MCP with Neo4j](https://www.wearedevelopers.com/magazine/604-everything-a-developer-needs-to-know-about-mcp-with-neo4j) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 210: AI Agents Are Go! Is MCP Dead? LLMs Crack Anonymity](https://www.wearedevelopers.com/magazine/709-dev-digest-210-ai-agents-are-go-is-mcp-dead-llms-crack-anonymity) - [Dev Digest 164: AI Agents, AI Blindspots and MCP security problems](https://www.wearedevelopers.com/magazine/578-dev-digest-164-ai-agents-ai-blindspots-and-mcp-security-problems)